Record summary

CVE-2007-2726 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.

Description

BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBBitsCast 0.13.0 - invalid string Remote Denial of ServiceExploitDB exploitby gbrNot analyzed1 file
ExploitDB

PoC details

References

5